Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc1ef3808e791f0e…

MALICIOUS

PDF

17.7 KB Created: 2020-03-18 23:24:08 +00:00 Authoring application: mPDF 5.7
MD5: 294947b7ab09589fc79a1641272c34df SHA-1: 3aeea20255b9c1fa4c5f4b9facf9a69d7cde44d4 SHA-256: bc1ef3808e791f0e8e8a350cd75cc157dddb6f8fe00723983d64452a8a9e9c84
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links pointing to external PDF files hosted on the domain 'weisncio.myhome.cx'. This behavior is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://weisncio.myhome.cx/1620625622621620628/Bound-to-the-Alpha-Part-One-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4624622625627623/Taming-the-Alpha-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620625622621621624/Claimed-by-the-Alphas-Part-Three-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4629623623629623/The-Dragon-s-Appraiser-Part-Three-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620625622621626620/Choices-Running-With-Alphas-3-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4624622625627622/Faith-Running-With-Alphas-5-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/4624624620621624/Home-Running-With-Alphas-7-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1620629624622628623/Grizzly-Bear-s-Bride-Greystone-Shifters-1-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/1625622621624628/Claimed-by-the-Alphas-Shifters-of-Appalachia-Book-1-by-Viola-Rivard.pdf
    • http://weisncio.myhome.cx/2629629628623628/Bound-to-My-Alpha-Boss-Packless-4-by-Fox-Hawkins.pdf
    • http://weisncio.myhome.cx/3626625621626627/One-Part-Human-An-Obscure-Magic-1-by-Viola-Grace.pdf
    • http://weisncio.myhome.cx/4626622622623627/Alpha-Billionaire-Part-III-Alpha-Billionaire-3-by-Helen-Cooper.pdf
    • http://weisncio.myhome.cx/6623621628624620/The-Alpha-s-Human---Part-Two-The-Alpha-s-Human-1-2-by-D-J-Heart.pdf
    • http://weisncio.myhome.cx/4626620622623627/Alpha-Fighter---Part-Two-The-Alpha-Fighter-2-by-Ava-Ashley.pdf
    • http://weisncio.myhome.cx/3622622620621626/New-Alpha-Rising-Ascension-Part-I-by-A-T-Russell.pdf
    • http://weisncio.myhome.cx/1627624622621623/The-Alphabet-Game-Part-Three---L-to-R-The-Alpha-Series-1-3-by-Andie-M-Long.pdf
    • http://weisncio.myhome.cx/1627624624622627/The-Alphabet-Game-Part-Two---F-to-K-The-Alpha-Series-1-2-by-Andie-M-Long.pdf
    • http://weisncio.myhome.cx/1620623627622625625/Final-Fantasy---Final-Fantasy-XII-Enemies-Abaddon-Abysteel-Adamantitan-Aeronite-Air-Chaosjet-Air-Elemental-Alpha-Hyena-Alpha-Wolf-Alpha-Worgen-Alraune-Alraune-King-Antares-Archaeoaevis-Archaeosaur-Ash-Wyrm-Axebeak-Babil-Bagoly-Baknam-by-Source-Wikipedia.pdf
    • http://weisncio.myhome.cx/3629620624628628/Bound-by-Honor-Bound-by-Love-Native-American-Romance-3-by-Ruth-Ann-Nordin.pdf
    • http://weisncio.myhome.cx/7625622623620627/Bound-by-Vengeance-Ravage-MC-Bound-3-by-Ryan-Michele.pdf
    • http://weisncio.myhome.cx/6623621628624620/The-Alpha-s-Human---Part-Two-The-Alpha-s-